ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Topic

cosign

2 posts

Plate 13

Cosign + SBOM in CI: Sign and Attest a Container Image in One Workflow

One CI shape: build an image by digest, Syft SBOM, Cosign sign + SBOM attest, verify success, and prove wrong-key/unsigned failure — the operational follow-on to after-xz.

Summary29 Sept 2026 · 8 min

Plate 11

After xz: A Practical Supply-Chain Checklist for Solo and Small Teams

Turn the xz-utils backdoor lesson into action: tarball vs git diffs, SBOM, Sigstore Cosign, SLSA provenance, and a solo/small-team release gate you can run this week.

Summary29 Sept 2026 · 9 min
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove